VDB
CVE-2016-3088
CVE-2016-3088
PUBLISHED
KEV
CVSS 9.800000190734863 CRITICAL
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.
EPSS 98.52% · 99.9th percentile
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
98.52%
99.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:Pro:16.04:LTS | activemq | *, 0, 5.13.2+dfsg-2 |
Timeline
- CVE Published
- Aug 17, 2015 PoC Published
- Dec 3, 2016 PoC Published
- Jun 29, 2017 PoC Published
- Jun 29, 2017 PoC Published
- May 10, 2018 PoC Published
- May 29, 2018 PoC Published
- Sep 19, 2018 VulnCheck KEV Exploitation
- Sep 19, 2018 PoC Published
- Feb 6, 2019 PoC Published
- Sep 1, 2019 VulnCheck KEV Exploitation
- Oct 21, 2019 PoC Published
References
- https://ubuntu.com/security/CVE-2016-3088 third-party-advisory
- http://activemq.apache.org/security-advisories.data/CVE-2016-3088-announcement.txt third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2016-3088 third-party-advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog third-party-advisory
- Nuclei Template exploit